Docker Blog · @docker
4 followers · 12 posts · Server techhub.social
Chris Bohnert · @bohnert
25 followers · 84 posts · Server social.vivaldi.net

Had coffee with a colleague from the team this morning talking about s (software bill of materials). Now is stuck in my head singing about something entirely different. You’re welcome. youtu.be/WZ32gSLNHfA

#security #sbom #tomjones #infosec #earworm

Last updated 1 year ago

Jay Cuthrell · @jay
107 followers · 484 posts · Server cuthrell.com
Open Source Initiative :osi: · @osi
3502 followers · 422 posts · Server social.opensource.org

GitHub added over 17.5 million new package licenses sourced from ClearlyDefined, expanding the license coverage for packages that appear in dependency graph and a repository's .

github.blog/changelog/2023-07-

#sbom

Last updated 1 year ago

OpenSSF · @openssf
266 followers · 104 posts · Server social.lfx.dev

Everywhere & the Security Tooling Working Group: Providing the Best Security Tools for Open Source Developers openssf.org/blog/2023/06/30/sb

#sbom

Last updated 1 year ago

Jay Cuthrell · @jay
103 followers · 426 posts · Server cuthrell.com
Felix Bartels · @felix
53 followers · 196 posts · Server toot.9wd.eu

Earlier this year I experimented a bit with the integration of , not only to know our dependencies, but also to track their individual to make sure we were compliant. Unfortunately, it didn't really fit into our pipeline yet and would require some plumbing changes.

#docker #sbom #licences #gitlab

Last updated 1 year ago

Felix Bartels · @felix
53 followers · 195 posts · Server toot.9wd.eu

I just stumbled across an interesting blog by @vmbrasseur. In anonymoushash.vmbrasseur.com/2 she gives an introduction to Software Bill of Materials, or for short. In a world where the complexity of software is only increasing due to the reliance on rapidly changing third-party code, it is a good initiative to see where all your dependencies are and where the potential risks lie.

#sbom

Last updated 1 year ago

OpenSSF · @openssf
215 followers · 99 posts · Server social.lfx.dev

Why Generators Need to Accurately Represent Open Source Licenses by Surendra Pathak, Interlynk openssf.org/blog/2023/06/20/wh

#sbom

Last updated 1 year ago

OpenSSF · @openssf
213 followers · 90 posts · Server social.lfx.dev

On Wed, June 14th, CISA is facilitating an SBOM-a-Rama in Los Angeles & the event is open to anyone. More info at: cisa.gov/news-events/events/sb

#sbom

Last updated 1 year ago

Jay Cuthrell · @jay
102 followers · 361 posts · Server cuthrell.com
Snyk · @snyk
7 followers · 4 posts · Server masto.dsoc.io

✨ New blog post: How to generate an for and applications!

In this post, @lirantal details how to use the Snyk API or Snyk CLI to generate an SBOM for Node.js applications.

snyk.co/ufJ9G

#sbom #javascript #nodejs

Last updated 1 year ago

Volkan Özçelik · @volkan
37 followers · 1231 posts · Server z2h.dev

validkube: paste your k8s yaml to validate, clean, secure, audit, and sbom.

validkube.com

#tools #security #kubernetes #validkube #yaml #validator #sbom #infra

Last updated 2 years ago

Apereo Foundation · @apereo
62 followers · 228 posts · Server social.fossdle.org

Something for to think about?

"When the and Infrastructure Security Agency () announced guidelines promoting better security of the software supply chain, the agency touted the software bill of materials () as 'a key building block in security and software supply chain risk management.'”

"One of the key areas is to improve around software, and it is expected that the SBOM will play an important role."

securityboulevard.com/2023/04/

#highered #cybersecurity #cisa #sbom #security #opensource #edtech

Last updated 2 years ago

VM (Vicky) Brasseur · @vmbrasseur
1567 followers · 1212 posts · Server social.vmbrasseur.com

📖 Software Bill of Materials ( )

Those who wish to incorporate SBOMs into their processes must deal with the growing pains of an evolving ecosystem.

anonymoushash.vmbrasseur.com/2

#sbom #foss #opensource #softwaresupplychain

Last updated 2 years ago

Jay Cuthrell · @jay
86 followers · 286 posts · Server cuthrell.com

🎙️ ✨ A new episode has been published on @ITSPmagazine

Show: ITSPmagazine Event Coverage: RSAC 2023 San Francisco, USA With @Marcociappelli and @seanmartin

Episode: The Importance of Software Bill-of-Materials (SBOMs)

Guest: Allan Friedman

Podcast format: Audio & Video

Enjoy!

👉 itspmagazine.com/rsa-conferenc

#sbom #cisa #rsaconference #rsac2023 #rsaccoverage #cybersecurity #infosec #tech #Technology

Last updated 2 years ago

· @twitter
1 followers · 44792 posts · Server mstdn.skullb0x.io

Referenced link: hubs.la/Q01JHmXY0
Originally posted by The Linux Foundation / @linuxfoundation@twitter.com: twitter.com/linuxfoundation/st

Big news: GitHub introduces self-service SBOMs, meaning all GitHub projects can now export a software bill of materials!

Learn more on the GitHub blog: hubs.la/Q01JHmXY0
@github

#github #sbom #opensource #CyberSecurity

Last updated 2 years ago

GitHub · @github
2 followers · 11 posts · Server techhub.social
OpenSSF · @openssf
121 followers · 26 posts · Server social.lfx.dev